PESCAN.IO - Analysis Report Basic

File Structure
Analysis Image
PE Chart Code
Header PE (light blue)
Executable sections (pink)
Non-executable sections (black)
External injected code (red)
File Structure in red = malformed or corrupted header

Chart Code For Other Files
Printable characters (blue)
Non-printable characters (black)
Information
Icon: Icon
Size: 5,68 MB
SHA-256 Hash: B8CF4FC945A0C0401F6931467F4DDF2F58A017E932A87B3DDAA0BB925EF78231
SHA-1 Hash: 41E707866B91BF5509091B0949FCCAA8CBE73908
MD5 Hash: 6A0748CEF7672D8C10DA160A9F9D3E7C
Imphash: BA5546933531FAFA869B1F86A4E2A959
MajorOSVersion: 5
MinorOSVersion: 2
CheckSum: 005BB998
EntryPoint (rva): A6A0
SizeOfHeaders: 400
SizeOfImage: 64000
ImageBase: 0000000140000000
Architecture: x64
ImportTable: 3BB94
IAT: 2A000
Characteristics: 22
TimeDateStamp: 66E87CD8
Date: 16/09/2024 18:45:44
File Type: EXE
Number Of Sections: 7
ASLR: Disabled
Section Names (Optional Header): .text, .rdata, .data, .pdata, _RDATA, .rsrc, .reloc
Number Of Executable Sections: 1
Subsystem: Windows Console
UAC Execution Level Manifest: asInvoker

Sections Info
Section Name Flags ROffset RSize VOffset VSizeEntropyChi2
.text
0x60000020
Code
Executable
Readable
400 28A00 1000 28890
6.49
985097.13
.rdata
0x40000040
Initialized Data
Readable
28E00 12800 2A000 1271A
5.8463
2031601.31
.data
0xC0000040
Initialized Data
Readable
Writeable
3B600 E00 3D000 103F8
1.8089
589999.57
.pdata
0x40000040
Initialized Data
Readable
3C400 2200 4E000 20E8
5.331
276673
_RDATA
0x40000040
Initialized Data
Readable
3E600 200 51000 15C
2.7954
58140
.rsrc
0x40000040
Initialized Data
Readable
3E800 11000 52000 10EB6
3.8281
3844078.33
.reloc
0x42000040
Initialized Data
GP-Relative
Readable
4F800 800 63000 75C
5.2389
17470.25
Binder/Joiner/Crypter
Dropper code detected (EOF) - 5,29 MB

Entry Point
The section number (1) have the Entry Point
Information -> EntryPoint (calculated) - 9AA0
Code -> 4883EC28E8670200004883C428E96AFEFFFFCCCCCCCCCCCCCCCCCCCCCCCCCCCC4883EC28E8AF07000085C0742165488B0425
Assembler
|SUB RSP, 0X28
|CALL 0X14000A910
|ADD RSP, 0X28
|JMP 0X14000A51C
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|INT3
|SUB RSP, 0X28
|CALL 0X14000AE78
|TEST EAX, EAX
|JE 0X14000A6EE
Signatures
Rich Signature Analyzer:
Code -> C7A91E8483C870D783C870D783C870D7C8B073D684C870D7C8B075D63DC870D7C8B074D689C870D7CCB48DD780C870D7CCB475D6ABC870D7CCB474D692C870D7CCB473D68AC870D7C8B071D686C870D783C871D7F6C870D742B474D697C870D742B472D682C870D75269636883C870D7
Footprint md5 Hash -> 06764C53FA54C90C6F35C5AC28ACAF10
• The Rich header apparently has not been modified
Certificate - Digital Signature Not Found:
• The file is not signed

Packer/Compiler
Detect It Easy (die)
PE+(64): packer: PyInstaller(-)[-]
PE+(64): compiler: Microsoft Visual C/C++(-)[-]
PE+(64): linker: Microsoft Linker(14.34**)[-]
PE+(64): overlay: zlib archive(-)[-]
Entropy: 7.97916

Suspicious Functions
Library Function Description
KERNEL32.DLL WriteFile Writes data to a specified file or input/output (I/O) device.
KERNEL32.DLL GetProcAddress Retrieves the address of an exported function or variable from the specified dynamic-link library (DLL).
KERNEL32.DLL IsDebuggerPresent Determines if the calling process is being debugged by a user-mode debugger.
File Access
%s%c%s.exe
6python310.dll
bpython310.dll
blibssl-1_1.dll
blibcrypto-1_1.dll
bVCRUNTIME140.dll
ADVAPI32.dll
KERNEL32.dll
Path of ucrtbase.dll
ucrtbase.dll
.dat
@.dat
xbase_library.zip
base_library.zip
Temp

File Access (UNICODE)
mscoree.dll

Interest's Words
exec
attrib
start
ping
expand
replace

URLs
http://schemas.microsoft.com/SMI/2016/WindowsSettings

Strings/Hex Code Found With The File Rules
Rule Type Encoding Matched (Word)
Text Ascii WinAPI Sockets (connect)
Text Ascii File (GetTempPath)
Text Ascii File (CreateFile)
Text Ascii File (WriteFile)
Text Ascii File (ReadFile)
Text Ascii Anti-Analysis VM (IsDebuggerPresent)
Text Ascii Reconnaissance (FindNextFileW)
Text Ascii Reconnaissance (FindClose)
Text Ascii Stealth (CloseHandle)
Text Ascii Execution (CreateProcessW)
Entry Point Hex Pattern LX-Exe Executable Image
Entry Point Hex Pattern Microsoft Visual C++ 8.0 (DLL)
Entry Point Hex Pattern Microsoft Visual C++ 8.0
Entry Point Hex Pattern PE-Exe Executable Image
Resources
Path DataRVA Size FileOffset CodeText
\ICON\1\0 520E8 10828 3E8E8 2800000080000000000100000100200000000000000001001C7600001C760000000000000000000000000000000000000000(............. ..........v...v....................
\GROUP_ICON\0\0 62910 14 4F110 0000010001008080000001002000280801000100............ .(.....
\24\1\0 62924 592 4F124 3C3F786D6C2076657273696F6E3D22312E302220656E636F64696E673D225554462D3822207374616E64616C6F6E653D2279<?xml version="1.0" encoding="UTF-8" standalone="y
Intelligent String
• %s%c%s.pkg
• %s%c%s.exe
• ucrtbase.dll
• base_library.zip
• status_texttk.tcl
• .exe
• .cmd
• .bat
• .com
• mscoree.dll
• .bss
• ADVAPI32.dll
• <longPathAware xmlns="http://schemas.microsoft.com/SMI/2016/WindowsSettings">true</longPathAware>
• .rMh
• X.qNJ
• b_bz2.pyd
• b_decimal.pyd
• b_hashlib.pyd
• b_lzma.pyd
• b_socket.pyd
• b_ssl.pyd
• blibcrypto-1_1.dll
• blibssl-1_1.dll
• bpython310.dll
• bselect.pyd
• bunicodedata.pyd
• xbase_library.zip
• zPYZ-00.pyz
• 6python310.dll

Flow Anomalies
Offset FlowVA Section Description
10D7 N/A .text CALL QWORD PTR [RIP+0x2841B]
1939 N/A .text CALL QWORD PTR [RIP+0x27E21]
196E N/A .text CALL QWORD PTR [RIP+0x27DEC]
1A11 N/A .text CALL QWORD PTR [RIP+0x27D49]
1A2E N/A .text CALL QWORD PTR [RIP+0x27D2C]
1A3E N/A .text CALL QWORD PTR [RIP+0x27D1C]
1A51 N/A .text CALL QWORD PTR [RIP+0x27D09]
1A77 N/A .text CALL QWORD PTR [RIP+0x27CE3]
1A8D N/A .text CALL QWORD PTR [RIP+0x27CCD]
1AFD N/A .text CALL QWORD PTR [RIP+0x27C5D]
1B2F N/A .text CALL QWORD PTR [RIP+0x27C2B]
1DD5 N/A .text CALL QWORD PTR [RIP+0x2770D]
2101 N/A .text CALL QWORD PTR [RIP+0x273D9]
2336 N/A .text CALL QWORD PTR [RIP+0x2719C]
2375 N/A .text CALL QWORD PTR [RIP+0x2715D]
239A N/A .text CALL QWORD PTR [RIP+0x27138]
23BF N/A .text CALL QWORD PTR [RIP+0x27113]
23E7 N/A .text CALL QWORD PTR [RIP+0x270EB]
240F N/A .text CALL QWORD PTR [RIP+0x270C3]
2437 N/A .text CALL QWORD PTR [RIP+0x2709B]
245F N/A .text CALL QWORD PTR [RIP+0x27073]
2487 N/A .text CALL QWORD PTR [RIP+0x2704B]
24B7 N/A .text CALL QWORD PTR [RIP+0x2701B]
24DF N/A .text CALL QWORD PTR [RIP+0x26FF3]
2507 N/A .text CALL QWORD PTR [RIP+0x26FCB]
252F N/A .text CALL QWORD PTR [RIP+0x26FA3]
2557 N/A .text CALL QWORD PTR [RIP+0x26F7B]
257F N/A .text CALL QWORD PTR [RIP+0x26F53]
25A7 N/A .text CALL QWORD PTR [RIP+0x26F2B]
25CF N/A .text CALL QWORD PTR [RIP+0x26F03]
25F7 N/A .text CALL QWORD PTR [RIP+0x26EDB]
261F N/A .text CALL QWORD PTR [RIP+0x26EB3]
2647 N/A .text CALL QWORD PTR [RIP+0x26E8B]
266F N/A .text CALL QWORD PTR [RIP+0x26E63]
2697 N/A .text CALL QWORD PTR [RIP+0x26E3B]
26BF N/A .text CALL QWORD PTR [RIP+0x26E13]
26E7 N/A .text CALL QWORD PTR [RIP+0x26DEB]
270F N/A .text CALL QWORD PTR [RIP+0x26DC3]
2737 N/A .text CALL QWORD PTR [RIP+0x26D9B]
275F N/A .text CALL QWORD PTR [RIP+0x26D73]
2787 N/A .text CALL QWORD PTR [RIP+0x26D4B]
27AF N/A .text CALL QWORD PTR [RIP+0x26D23]
27D7 N/A .text CALL QWORD PTR [RIP+0x26CFB]
27FF N/A .text CALL QWORD PTR [RIP+0x26CD3]
2827 N/A .text CALL QWORD PTR [RIP+0x26CAB]
284F N/A .text CALL QWORD PTR [RIP+0x26C83]
2877 N/A .text CALL QWORD PTR [RIP+0x26C5B]
289F N/A .text CALL QWORD PTR [RIP+0x26C33]
28C7 N/A .text CALL QWORD PTR [RIP+0x26C0B]
28EF N/A .text CALL QWORD PTR [RIP+0x26BE3]
2917 N/A .text CALL QWORD PTR [RIP+0x26BBB]
293F N/A .text CALL QWORD PTR [RIP+0x26B93]
2967 N/A .text CALL QWORD PTR [RIP+0x26B6B]
298F N/A .text CALL QWORD PTR [RIP+0x26B43]
29B7 N/A .text CALL QWORD PTR [RIP+0x26B1B]
29DF N/A .text CALL QWORD PTR [RIP+0x26AF3]
2A07 N/A .text CALL QWORD PTR [RIP+0x26ACB]
2A2F N/A .text CALL QWORD PTR [RIP+0x26AA3]
2A57 N/A .text CALL QWORD PTR [RIP+0x26A7B]
2A7F N/A .text CALL QWORD PTR [RIP+0x26A53]
2AA7 N/A .text CALL QWORD PTR [RIP+0x26A2B]
2ACF N/A .text CALL QWORD PTR [RIP+0x26A03]
2AF7 N/A .text CALL QWORD PTR [RIP+0x269DB]
2B1F N/A .text CALL QWORD PTR [RIP+0x269B3]
2B47 N/A .text CALL QWORD PTR [RIP+0x2698B]
2B6F N/A .text CALL QWORD PTR [RIP+0x26963]
2B97 N/A .text CALL QWORD PTR [RIP+0x2693B]
2BBF N/A .text CALL QWORD PTR [RIP+0x26913]
2C0D N/A .text CALL QWORD PTR [RIP+0x26B4D]
2C23 N/A .text CALL QWORD PTR [RIP+0x26B37]
2C35 N/A .text JMP QWORD PTR [RIP+0x26B25]
2C75 N/A .text CALL QWORD PTR [RIP+0x26AE5]
2CAD N/A .text CALL QWORD PTR [RIP+0x26AAD]
2CF9 N/A .text CALL QWORD PTR [RIP+0x26A61]
2D15 N/A .text CALL QWORD PTR [RIP+0x26A45]
2D36 N/A .text CALL QWORD PTR [RIP+0x26A24]
2D48 N/A .text CALL QWORD PTR [RIP+0x26A12]
2D55 N/A .text CALL QWORD PTR [RIP+0x26A05]
2DFF N/A .text CALL QWORD PTR [RIP+0x2695B]
2E1C N/A .text CALL QWORD PTR [RIP+0x2693E]
2E2F N/A .text CALL QWORD PTR [RIP+0x2692B]
2E43 N/A .text CALL QWORD PTR [RIP+0x26917]
2E64 N/A .text CALL QWORD PTR [RIP+0x268F6]
2E79 N/A .text CALL QWORD PTR [RIP+0x268E1]
3126 N/A .text CALL QWORD PTR [RIP+0x26634]
32E3 N/A .text CALL QWORD PTR [RIP+0x26477]
3324 N/A .text CALL QWORD PTR [RIP+0x26436]
33E4 N/A .text CALL QWORD PTR [RIP+0x26376]
33F8 N/A .text CALL QWORD PTR [RIP+0x26362]
340D N/A .text CALL QWORD PTR [RIP+0x2634D]
3421 N/A .text CALL QWORD PTR [RIP+0x26339]
3454 N/A .text CALL QWORD PTR [RIP+0x26306]
3486 N/A .text CALL QWORD PTR [RIP+0x262D4]
34F4 N/A .text CALL QWORD PTR [RIP+0x26266]
3530 N/A .text CALL QWORD PTR [RIP+0x2622A]
354C N/A .text CALL QWORD PTR [RIP+0x2620E]
3563 N/A .text CALL QWORD PTR [RIP+0x261F7]
3577 N/A .text CALL QWORD PTR [RIP+0x261E3]
35B3 N/A .text CALL QWORD PTR [RIP+0x261A7]
35C8 N/A .text CALL QWORD PTR [RIP+0x26192]
38045E-38046B N/A *padding* Potential obfuscated jump sequence detected, count: 7
3837BC-3837CB N/A *padding* Potential obfuscated jump sequence detected, count: 8
38DF6C-38DFBB N/A *padding* Potential obfuscated jump sequence detected, count: 40
39AA56-39AA63 N/A *padding* Potential obfuscated jump sequence detected, count: 7
3AFE1E-3AFE2E N/A *padding* Potential obfuscated jump sequence detected, count: 7
49A475-49A48E N/A *padding* Potential obfuscated jump sequence detected, count: 13
50000 N/A *Overlay* 78DA5D8FC16EC2300C40E3B69454ADB4FD4627C4 | x.]..n.0.@...T...F&#39;.
Extra Analysis
Metric Value Percentage
Ascii Code 4038944 67,7987%
Null Byte Code 99028 1,6623%
© 2026 All rights reserved.